
A compromised email inbox can be weaponized into full remote code execution on a victim’s machine, not through malware or phishing links, but by turning the victim’s own Claude Desktop assistant against them.
The attack uncovered by Security researchers at Pentera Labs began with access to a third-party platform that aggregates customer email inboxes, gained through an exploited authentication flow.
Rather than pursuing conventional password-reset or phishing routes, the team used inbox access to move laterally into the victim’s Claude account and identified the “Personal Preferences” field, a user-editable prompt that syncs across every device and session tied to the account, as the ideal attack surface.
Claude Desktop to Execute Remote Code
By injecting an encoded, non-obvious prompt into this synced field, the researchers caused Claude Desktop to silently adopt attacker-controlled instructions the moment the victim next opened the app, with no re-authentication or visible warning triggered.
The payload instructed Claude to enumerate installed command-capable extensions, such as the Desktop Commander MCP tool, and execute attacker-supplied commands through them.
If a command-capable extension was already present, Claude executed the malicious instructions automatically during a routine chat, requiring zero additional victim interaction.
If no such extension existed, Claude itself became the social-engineering vector: it displayed a convincing fake error message urging the user to install Desktop Commander, complete with a legitimate-looking install page.
Once installed, the next ordinary message from the victim triggered code execution, effectively turning the trusted assistant into a persistent command-and-control channel that could fetch and run rotating attacker commands.
Independent research has surfaced related weaknesses in Claude’s extension ecosystem. LayerX previously disclosed a zero-click RCE affecting Claude Desktop Extensions (DXT) that could be triggered through a maliciously worded calendar event, earning a CVSS score of 10.
Koi Security similarly found unsanitized command injection flaws in Anthropic’s own Chrome, iMessage, and Apple Notes connectors, rated CVSS 8.9 and since patched. Together, these findings point to a systemic pattern: local, code-executing extensions paired with natural-language trust create a broad attack surface.
Pentera reported its findings to Anthropic in November 2025. Anthropic acknowledged the research but declined to classify it as a security vulnerability, stating that “personal preferences, skills, and MCP connectors” are designed to execute code through Claude Desktop by intent, calling the behavior “expected functionality rather than a security vulnerability”.
The company noted that related safeguards are on its roadmap and pointed to existing session management and account authentication controls as mitigations, while emphasizing that the attack requires a prior account compromise.
Security teams are urged to treat AI desktop applications as privileged software capable of executing code and touching local files, monitor for unauthorized changes to synced assistant settings, and restrict which extensions can be paired with AI clients.
As AI assistants blur the line between chat interface and system agent, the gap between their perceived and actual capabilities is emerging as a distinct and currently under-monitored enterprise risk.
Stop Accepting SLAs Written for 2019 SOCs – Here’s the 2026 AI SLA Vendor Checklist – Download Free AI SOC SLA Guide
The post AI Double Agent Attack Turns Claude Desktop to Execute Remote Code on a Target Machine appeared first on Cyber Security News.
Discover more from RSS Feeds Cloud
Subscribe to get the latest posts sent to your email.
